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31 AUG 1978 


MEMORANDUM FOR: eputy Director of Central Intelligence 


FROM: John F. Blake = 
Deputy Director for Administration 

SUBJECT: Security Review - Interim Report 

REFERENCE: _ Memorandum for DOA from DOCT, dated 


18 August 1978, Subject: A Request 
for a Security Review and Assessment 


1. Action Requested: None; for Information only. 


2. Background: Following the mid-August 1978 revelation 
that a former Agency employee had sold classified information 
to the Soviets, you directed a comprehensive review of the 
Agency's security policies and procedures and called far an 
jnterina report by 1 September 1978. Subsequently, the Director 
has expanded the scope of the interim report to include: 
(a} a cataloguing of specific improvements in the Agency's 
Security program realized: since his appointment and by his 
initiatives; and (b) a listing of procedures currently being 
Snitiated to further improve the security of classified infor- 
mation. Pursuant to those directions, this interim report is 
submitted. 


. 3. Staff Position: In April 1977, following the reve- 
lations of the Moore and Boyce/Les espionage cases, a compre- 
hensive impact study was completed by the Office of Security. 

As 2 consequence, the Director caused several security initiatives 
and gave the necessary impetus to others which have been success~ 
fully implemented to the enhancement of Agency and Intelligence 
Comaunity security. Agency programs successfully implemented 
‘inelude: 


a. A rigorous staff personnel security 
reinvyestigation program 
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b. Expanded security education and raiudoc- 
trination efforts throughout the Agency. 


c. Enhancement of appraisal criteria in 
Industrial Security Approvals. 


d. Initiation of the Industrial Contractor 
Polygraph Program. 


e. Increased spot checks of briefcases, 
packages and parcels at all Agency facilities in 
the Washington Metropolitan aroa. 


f. Initiation of a program of unannouncad 
security audits of Agancy contractor facilities. 


g. Initiation of research to enhance security 
movement of classified information via Sanne: restatent 
security containers and to preclude unauthorized 
reproduction of documents via use of special paper, 
Special inks and other techniques. 


h. A personbl interest in and invalvement by 
the Director and senior Agency managers in the 
adjudication and panalty assessment procedures 


‘involving Agency employees who have yiolated. secu- 


rity regulations. 


Programs initiat wi by the Directoy te tighten the secu- 


of the jntelligence Community have included: 


a. The strengthening of the Director of Central 
Intelligence Security Committes as 3 focal point for 


reporting and tracking unauthorized disclasures and 


for raising security consciousness in tha Community. 

be. Maintaining a freeze since 1 June 1977 on the 
total number of sensitive compartmented clearances 94 
throughout the Community. 


c. Initiation of a program to revalidate security 


“clearances by effecting zero-based reviews in Intelli- 


gence Comminity and contractor facilitias. 


d. Directing contracting and legal szuthorities to 


Strengthen the security provisions of contracts between 


commercial firms and Intelligence organizations. 
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I can assure you the Director of Security has and 
is continuing to dedicate all available personnel resources, 
as well as his personal attention, to the programs outlined 
above. ‘ 
in accordance with your specific request af 18 August 
1978, a comprehensive review of the Agency's security policies 
and procedures has comnenced. 


During the week of 21 August the organization and 

staffing of a Security Review Task Force was undertaken. 

The Task Force will approach the review in three segments. 

Each seguant staff will function under the Readership of a 

senior experienced officer. The segments will address, 

separately, Personnel Security, Physical Security, and Infar- 

mation Control and Protection. The magnitude of the task 

is avesome, and the Director of Security estimates a conpre- 

hensive review will require a mininuw-of sixty (60) days. 
| 
| 
| 
| 
| 
| 
| 


The Persornel Security Segment of the Task Force 
intends to investigate all periods of an employee's career 
from prsemployment processing through post-employment counseling. 
Jt is their intent to survey personnel recruitment and assign- 
ment policies and procedures which are quite varled from 
directorate to directorate and from office to office. Although 
the emphasis in this segment will be on staff employees, the 
Task Fores will also survey the several other types of individuals 
who are utilized by ths Agency. The entire security clearance 
process from pre-field Investigation to final adjudication will 
be reviewed, as will the vast number of policies and procedures 
that pertain during the employment phase. 


The employment phase topics include security indoctri- 
nation/reindoctrination; marriage, including marriage to an 
alien; outside activities; handling of nisconduct incidents; 
counterintelligence review of high risk personnel and organiza- 
tional units; the relnvestigation progran; gacurity and 
suitability reviews for overseas candidates; Agency management 
responsibilities; and the Personnel Evaluation Board. Finally, 
‘the Agency's out-processing policies and procedures as well as 
current policies relative to post-employment counseling will be 
addressed under this segment. a 


The Task Force will exclude from its review the 
operational security policy procedures and practices concerning 
thoge individuals who are utilized by the Directorate of 
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Operations in an operational and informational capacity such 
as double agents and clandestine sources. That policy is a 
DDO responsibility. 


the Physical Security Segment has an enormous task 
at hand. This segment will limit the scope of their review 
by concentrating primarily upon the physical security program 
a3 it is pursued within the Headquarters Building. The sub- 
stantive areas which constitute the physical security program 
of the Agency can be examined in relation to operations within 
the Headquarters Building within a yeasonable time frame. 


; Essentially our physical security policies and praca- 
dures at Headquarters have been adopted in our domastic and 
overseas facilities, and available rasource and time constraints 
dictate that but cursory reference be given to the nature and 
scope of tha overseas and domestic facilities outside Washington 
during the survey. Similarly, this yoview will not specifically 
cover the physical security aspects of our ‘industrial security 


rouraa because that subject has been thoroughly reviewed during . 
prog g 


the past year. And finally, we consider the technical threat 
as well a3 the measures which have been implemented to caunter 
this threat as beyond the scope of this review. — 


The Physical Security Segment of the Task Force will 
address thoroughly. the policies and procedures pertaining to: 
psrimeter security; building security; access controls for 
all types of people from staff employees ta vendors; badges; 
entry and exit inspection procedures; internal personnel control; 
storage of classified information; the Agency's guard program; 
intrusion detection systems and other monitoring equipment; 
after hours security procedures and the security violation pro- 
Tam. ‘ 
The Information Control and Protection Segnent pro- 
poses to review the application by CIA of directives and 
regulations governing the production, marking, classification, 
reproduction, transmission, inventory and overall control of 
classified information. These will be reviewed for current 
applicability to determina whether rules are baing observed, 
and, if so, whether a significant measure of control results 
fron their observance. The scope of this segment will include 
an inquiry into the level and efficiency of employee training 
in document control procedures; an examination of the posibility 
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of handling information at lower levels of classification 

or compartmentation; exploration of methods to reduce the 
amount of classified material retained in the Agency; inquiry 
into the efficacy of current ADP and microform information 
control, and the state of pre-planning for future Information 
technology requirements. Finally, we intend to examine alter- 
native ways of controlling accountability for classified 
materials, including automated techniquas. 


Obviously, to conduct the survey effectively, the 
Task Force will require the complete cooperation of the 
Agency's population. For example, to meaningfully describe 
current procedures undsr the Porsonneal Security Segment is 
going to require close cooperation with several offices, 
espacially the Office of Personnel and the Office of Medical 
Services. Furthermore, several offices throughout the Agency 
are involved in the recruitmant of personnel, and their 
cooperation will also be necessary. Consequently, it is recon- 
mended that you solicit the cooperation of all directorates, 
with the members of the Task Porce. : 


The Task Force will approach its task by extensive 
documentary reviews, personal interviews both within and 
external to the Agency, and by discussion within the Task 
Force which will lead to a series of recommendations concerning 

the Agency's security program. The Task Force members have 
been exhorted to approach the task, particularly the recoamen- 
dations, with absolute objectivity and personal integrity, as 
we view the review as an’ opportunity to assure our security 
policies and procedures are right for the tine. 


We envision a final report to be submitted to you 
by 3 November 1978. We expect that report to be in four 
parts: (a) a description of current policies and procedures; 
(b) analysis of current policies and procedures; (c) conclusions; 
and (d) recommendations. 


The current review will be thorough. We anticipate 
specific recommendations pertaining to the restatement of ‘the 
basic principle that Security is a command responsibility 
-within the Agency, i.e., the responsibility of each manager 
and supervisor. Furthermore, we expect to relate the apparent 
deterioration in security discipline in the operating componsnts 
vo the reduction of professional security positions in those 
components over the past decade; in ten years the number of 
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Security careesrists assigned to other TO's has dropped from 

169 to 89, thirty-nine of those positions were located over-~ 

seas and twenty-one were at Headquarters. Those issues 

require orderly analysis before recommending specific changes. | 
Nevertheless, the urgency of the pregent situation | 

calis for the implementation of improved procedures and new 

initiatives priory to completion of the formal review. Towards 

that end the following actions hava been taken: 


(a) Commencing 11 Saptembsar 1973 the briefcase, 
package inspection program will be expanded and can~- 
ducted by the Federal Protective Officers on a routine 
basis seven days a week and twenty-four hours a day. 


(b) Commencing imasdiately, systematic counter~ 
intelligence procedures will be established by the 
Office of Security to investigate employee accesses 
to secure areas outside of normal duty hours and to 
review the pattern of employee after-hours accesses 
to Headquarters area buildings. 


(c} The Office of Security currently has ordered 
active studies into two methods of controlling documant 
‘yeproduction. One concepe involves the nodification 
of reproduction equipment to house a badge reader 
which would maintala accountability for all conies 
made at least to the extent of maintaining an audit 
trail of an individual enployse's use of the equipment. 
The other concept involves davelopment of a paper or 
print process wnich is not copiable. 


(d) The Deputy Directors of the Agency are being 
‘directed, immediatealy,. to establish positive, account~ 
able document controls for particularly sensitive 
materials under their cognizance. 


{e} Arrangements are being finalized for the 

Office of Security to conduct a series of briefings 
of senior staffs throughout the Agency. The briefings 
‘will comprehensively review security problems discovered 
during the past several months through the reinvesti- 

gation program, briefcase inspection program, etc., 
end will reemphasizs the command and managerial respon- 
sibility in implementing sound security practices. 
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(£) The Office of Security is reminding Agency 
managers that personnel are available as speakers, 
panelists, consultants, etc, to assist command chan- 
nels in the security education and reindectrination 
of small employes grou'ys. As you know, the Office 
of Security recently completed a formal reindoctri- 
nation of the Agency population in a number of. 
presentations to large audiences. 


4. Conclusion: In accordance with the reference, I 
assure you that the Security Review is receiving the highest 
priority and my personal attention. The scope of the task, 
in my opinion, fully justifies a 3 November 1978 final reporting 
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obert W. Gambino Date 
Director of Security ; 
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